ADA-C01 exam dumps

ADA-C01 practice question 90 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 90

Single answerReset passwords and temporarily disable MFA for users

A Snowflake administrator receives an urgent request from a finance analyst who replaced their mobile phone and can no longer complete MFA during login. The analyst must regain access immediately for end-of-quarter reporting, but the company wants to keep MFA enforced for all users in the long term. Assuming the administrator has the required privileges, which action is the MOST appropriate to restore access while aligning with Snowflake administration best practices?

  1. A

    Use ALTER USER to reset the user's password and temporarily disable MFA for that user, then require the user to re-enroll MFA after access is restored.

  2. B

    Disable the network policy on the account so the user can log in without MFA from any location, then re-enable it later.

  3. C

    Grant the user the ACCOUNTADMIN role so they can update their own MFA settings and password.

  4. D

    Drop and recreate the user with the same name so MFA enrollment is cleared and the user can log in again.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use targeted user administration rather than changing broader security controls or elevating privileges. In Snowflake, administrators with the proper authority can reset a user's password and temporarily disable MFA for that specific user, allowing the user to log in and complete MFA re-enrollment. This approach is consistent with the principles of least privilege, minimal blast radius, and operational continuity. By contrast, network policies govern IP-based access restrictions rather than MFA state, ACCOUNTADMIN should not be granted to end users for self-recovery, and dropping/recreating users is unnecessarily disruptive. Snowflake documentation on user management and MFA administration describes administrative recovery actions such as password resets and temporary MFA disablement for users who lose access to their MFA device.

  • A. Correct.

    Correct. In this scenario, the administrator should address the individual user's access problem directly rather than weakening account-wide controls. Snowflake supports administrative actions to reset a user's password and temporarily disable MFA for that user so they can regain access and re-register MFA. This is the least disruptive and most targeted approach, and it preserves the organization's long-term MFA requirement.

  • B. Incorrect.

    Incorrect. Network policies control allowed client IP addresses, not MFA enrollment or MFA challenges. Disabling a network policy would broaden access exposure and would not appropriately solve the user's lost MFA device problem. This option reflects a common misconception that network access controls and authentication factors are interchangeable.

  • C. Incorrect.

    Incorrect. Granting ACCOUNTADMIN violates least-privilege principles and is not an appropriate way to let an end user manage their own authentication recovery. High-privilege roles should not be assigned to resolve routine login issues, especially for business users. The administrator should perform the recovery action instead.

  • D. Incorrect.

    Incorrect. Dropping and recreating the user is overly destructive and can affect grants, ownership, audit continuity, and object relationships unless carefully transferred and rebuilt. It is not a best-practice method for resolving a lost MFA device or password reset scenario when Snowflake provides direct administrative recovery options.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam